A civic GPO grants local administrator rights on workstations to a broad user group. Why is this a significant AD-related finding?
Select an answer to reveal the explanation.
Short Explanation
Handing local admin to a big user crowd is like leaving spare house keys under every doormat. Once someone has one workstation key, hopping to the next desk gets easy. Call out that GPO sprawl.
Full Explanation
Group Policy that assigns local administrator rights to large populations creates widespread high-privilege footholds on endpoints. That condition supports credential theft and lateral movement themes even when the right is delivered by GPO rather than a nested domain group alone. It is not limited to cosmetic desktop settings. Reducing local admin sprawl is a standard hardening recommendation in AD environments.